Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form

Configure Windows LAPS Management with Microsoft Intune

Posted on 29/04/202315/08/2026 Imoh Etuk By Imoh Etuk No Comments on Configure Windows LAPS Management with Microsoft Intune
  1. Home
  2. AWS/Azure/OpenShift
  3. Configure Windows LAPS Management with Microsoft Intune
Microsoft-LAPS

In this post, I will show you how to Configure Windows LAPS Management with Microsoft Intune. Windows LAPS management with Intune is simple and straightforward. You can also modify Windows 11 Taskbar via Intune and GPO. There are a lot you can do with Intune such as managing Windows Defender Antivirus Through Microsoft Endpoint Manager Admin Dashboard and Intune. On April 11, 2023, Microsoft announced that new LAPS capabilities were coming directly to your devices.

The LAPS comes with new security updates. It is compatible with Windows editions: Windows 11 Pro, EDU, and Enterprise, Windows 10 Pro, EDU, and Enterprise, Windows Server 2022 and Windows Server Core 2022, and Windows Server 2019.

With LAPs, IT Administrators can encrypt and protect local administrator credentials using the Windows Local Administrator Password Solution (Windows LAPS), a feature of Windows. This includes backing up the passwords to Azure Active Directory or Active Directory and rotating them automatically. Below is a video on how LAPS works.

Using Microsoft Intune, you may set up Windows LAPS on your Windows workstations. See this related post to learn what ADK, MDT, Microsoft Endpoint Configuration Manager (SCCM), Intune, Autopilot, and WSUS is all about.

What is LAPS, and why do we need it?

The “Local Administrator Password Solution” (LAPS) allows domain-joined workstations to manage local account passwords. Only authorized users are able to access or request the reset of passwords since they are stored in Active Directory (AD) and secured by ACL.

Password management can become a difficult problem when users must log on to devices without domain credentials (such as local admin). The possibility of a Pass-the-Hash (PtH) credential replay attack is significantly increased in such environments.

Using a common local account with the same password on each machine in a domain is a problem that LAPS addresses. Please see how to configure Windows LAPS in Active Directory.

This problem is fixed by LAPS by assigning a unique, random password to each machine in the domain for the common local administrator account. By utilizing the solution, domain administrators can identify which individuals, such as help desk administrators, are permitted to access passwords.

Please see how to Install Windows Admin Center on Windows 10 and Windows 11, and how to schedule and run updates via Windows Admin Center.

Configuring LAPS with Microsoft Intune

To configure LAPS with Intune, follow the below steps:

Step 1: Create an Account Protection Policy. Visit the Microsoft Intune Portal and navigate to Endpoint Security > Account Protection> + Create Policy

creating-account-policy
Account Protection Creation Page

In the Platform field, select Windows 10 or later and in the Profile, select Local admin password solution (Windows LAPS) and click on Create.

create-profile-section
Creating Profile Policy

Specify a unique name for your new policy and description (optional) and then click Next

specifying-policy-name
Specifying the Policy Name

On the configuration page, in the Backup Directory field, select Backup the password to Azure AD only.

policy-config-page-1
Configuring the Policy

You can learn more about the above configuration settings in the official documentation maintained by Microsoft.

Skip the scope tags page and move directly to the Assignments tab. When you are there, assign the new policy to a device group, or all devices.

select-group
Assigning New Policy to All Devices

In the Review + Create pane, confirm the policy meets your requirements before creating it.

review-create-page
Review and Create

Accessing the Local Admin Password of a Device

There are a number of options for an administrator to view the local administrator password. These include PowerShell, Microsoft Entra, and the Intune Admin Portal. Here, we are just going to view it through Microsoft Entra Admin Center.

Please see how to use GitHub as Source Provider to AWS CodePipeline, how to add and remove Multiple Virtual Desktops in Windows 10 Multitasking, How to configure Pleasant Password MsSQL SSO, how to create a Mapped Drive via GPO Preferences and how to delete Apps from Launchpad on Mac

Viewing Using Microsoft Entra

Visit the Microsoft Entra admin portal. Check through the left pane under Azure Active Directory, click on Devices, then click All Devices.

List-of-Devices
All Devices

Now click on the device of your choice and then click on Show local administrative password to view it.

show-local-admin-passwd
Viewing Local Administrative Password from Intune Dashboard

In this post, you have learned how to Configure Windows LAPS Management with Microsoft Intune. Microsoft Intune. Microsoft Intune is a Microsoft cloud-based unified endpoint management service for both corporate and BYOD devices.

It extends some of the “on-premises” functionality of Microsoft Endpoint Configuration Manager to the Microsoft Azure cloud.

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
AWS/Azure/OpenShift, Security | Vulnerability Scans and Assessment, Windows Tags:microsoft, Microsoft Windows, Windows 10, Windows 11

Post navigation

Previous Post: How to use GitHub as Source Provider for AWS CodePipeline
Next Post: Various ways to restart an AWS EC2 instance

Related Posts

  • azure cost analysis
    Cost Management in Azure Using Cost Analysis Tool AWS/Azure/OpenShift
  • Featured image 1
    How to enable or disable color filters in Windows Windows
  • servicechannels3 1
    Long Term Servicing Branch vs Semi-Annual Channel Windows
  • Bulk operations in Azure AD
    Perform Bulk User Operations in Azure AD AWS/Azure/OpenShift
  • xxxxxx 1
    Display Windows system information via the Windows registry Windows
  • CAL Removal
    How to Remove and Manage RDS Licenses Web Server

More Related Articles

azure cost analysis Cost Management in Azure Using Cost Analysis Tool AWS/Azure/OpenShift
Featured image 1 How to enable or disable color filters in Windows Windows
servicechannels3 1 Long Term Servicing Branch vs Semi-Annual Channel Windows
Bulk operations in Azure AD Perform Bulk User Operations in Azure AD AWS/Azure/OpenShift
xxxxxx 1 Display Windows system information via the Windows registry Windows
CAL Removal How to Remove and Manage RDS Licenses Web Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

vexpert-badge-stars-5

Virtual Background

VEEAMLEGEND

Categories

veeaam100

Veeam Vanguard

  • Install Microsoft PKI ADCS
    Set up Microsoft PKI (ADCS) for SystoLOCK via PowerShell Windows Server
  • FailedRegistration
    DNS Bad key 9017: The Cluster Name registration failed of one or more associated DNS names Virtualization
  • remote desktop connection tabs rdp tabs
    Guide to Remote Desktop Connection Properties for Secure Access Windows
  • Featured image 5
    How to uninstall and prevent the installation of Microsoft Teams on Windows Windows
  • Slide2 1
    How to deploy WordPress on Azure App Service AWS/Azure/OpenShift
  • Windows 10 logo wmskill.com
    Handy Shutdown commands available in Windows Windows
  • featuredpkg
    How to solve /var/lib/dpkg/lock Error in Ubuntu Linux Linux
  • mbamclient
    How to deploy MBAM Client as part of a Windows Deployment Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,759 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Contact
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon
  • Bsky

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.